sigstore

package
v0.2.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: May 12, 2026 License: MIT Imports: 18 Imported by: 0

Documentation

Overview

Package sigstore implements the AnchorProvider interface using the Sigstore Rekor transparent log (https://rekor.sigstore.dev).

Rekor is a transparency log operated by the Linux Foundation / Sigstore project. Entries are append-only and immediately verifiable — once a log entry is created it is permanent, so Confirmation is returned as Finalized immediately after a successful Anchor call.

Implementation

Each Anchor call generates an ephemeral ECDSA P-256 key pair, signs the Merkle root hash, and submits a hashedrekord v0.0.1 entry to Rekor via the github.com/sigstore/rekor Go client. The returned log entry UUID is stored as ExternalID and in ProofData for subsequent Verify calls.

For pilot / proof-of-concept use, the ephemeral signing key is not persisted. In production, a stable identity key should be used so that the signing identity is independently verifiable.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Config

type Config struct {
	// RekorURL is the base URL of the Rekor instance.
	// Defaults to "https://rekor.sigstore.dev" when empty.
	RekorURL string `json:"rekor_url,omitempty"`
}

Config holds configuration for the Sigstore Rekor anchor provider.

type Provider

type Provider struct {
	// contains filtered or unexported fields
}

Provider implements providers.AnchorProvider using Rekor.

func NewProvider

func NewProvider(cfg Config) (*Provider, error)

NewProvider creates a new Sigstore Rekor anchor provider. Uses https://rekor.sigstore.dev by default.

func (*Provider) Anchor

Anchor submits the Merkle root to the Rekor transparency log as a hashedrekord v0.0.1 entry. An ephemeral ECDSA P-256 key is generated per anchor to satisfy Rekor's signature requirement.

Returns Confirmation: Finalized immediately — Rekor entries are permanent once accepted into the append-only log.

func (*Provider) Cost

func (p *Provider) Cost(_ int) providers.Cost

Cost returns the cost model for Sigstore Rekor (always free).

func (*Provider) Name

func (p *Provider) Name() string

Name returns the provider's stable identifier.

func (*Provider) Verify

func (p *Provider) Verify(ctx context.Context, anchor providers.Anchor) (providers.Verification, error)

Verify checks that the Rekor log entry still exists (expected always true for a properly operating transparency log). Implements swallow-transient-errors contract (§ 3.5c):

  • Network errors and 5xx responses → Swallowed=true, confirmation preserved.
  • 404 (entry missing from transparency log) → hard error (unexpected: log is append-only).
  • Malformed ProofData → hard error.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL